VYPR
Medium severity6.1OSV Advisory· Published Mar 30, 2019· Updated Jun 17, 2026

CVE-2019-10646

CVE-2019-10646

Description

Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.

Affected products

3
  • Wolfcms/WolfCMSOSV2 versions
    0.7.0, 0.7.1, 0.7.2, …+ 1 more
    • (no CPE)range: 0.7.0, 0.7.1, 0.7.2, …
    • cpe:2.3:a:wolfcms:wolf_cms:0.8.3.1:*:*:*:*:*:*:*
  • Range: =0.8.3.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.